Skip to content

Malware

Elirks

Elirks is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems.

Elirks is a Windows malware family.

Background

First seen in 2010, Elirks is a simple backdoor Trojan whose main purpose is exfiltrating data from infected machines, with most of its activity concentrated in East Asia. A distinctive trait is the way it obtains its C2 address: rather than hardcoding it, the malware queries a predetermined microblog or SNS account where the operators have, ahead of distribution, posted encoded IP addresses or domain names pointing to the actual C2 servers. In recent years, several Elirks variants have relied on Japanese blogging platforms for this purpose.


Source: Malpedia (Fraunhofer FKIE).